From f241fea7ee0a570138fa4e1b503fc12e9d22c14f Mon Sep 17 00:00:00 2001 From: nikoladev <15011519+nikoladev@users.noreply.github.com> Date: Fri, 3 Apr 2020 19:03:04 +0200 Subject: [PATCH] fix decompress vulnerability https://www.npmjs.com/advisories/1217 --- yarn.lock | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/yarn.lock b/yarn.lock index be841543d0d52..ddbcf053cf649 100644 --- a/yarn.lock +++ b/yarn.lock @@ -8310,8 +8310,9 @@ decompress-unzip@^4.0.1: yauzl "^2.4.2" decompress@^4.0.0, decompress@^4.2.0: - version "4.2.0" - resolved "https://registry.yarnpkg.com/decompress/-/decompress-4.2.0.tgz#7aedd85427e5a92dacfe55674a7c505e96d01f9d" + version "4.2.1" + resolved "https://registry.yarnpkg.com/decompress/-/decompress-4.2.1.tgz#007f55cc6a62c055afa37c07eb6a4ee1b773f118" + integrity sha512-e48kc2IjU+2Zw8cTb6VZcJQ3lgVbS4uuB1TfCHbiZIP/haNXm+SVyhu+87jts5/3ROpd82GSVCoNs/z8l4ZOaQ== dependencies: decompress-tar "^4.0.0" decompress-tarbz2 "^4.0.0"